CVE-2026-24869
8.1Mozilla · Firefox
A use-after-free vulnerability exists in the Layout: Scrolling and Overflow component of Mozilla Firefox, potentially allowing remote code execution when processing malicious content.
Executive summary
Mozilla Firefox contains a use-after-free vulnerability in the layout engine that could allow an attacker to achieve remote code execution via a specially crafted web page.
Vulnerability
This is a use-after-free memory corruption flaw located in the Layout: Scrolling and Overflow component. The vulnerability requires user interaction, as the attacker must entice a user to visit a malicious website or interact with crafted content to trigger the flaw.
Business impact
The vulnerability is rated as High with a CVSS score of 8.1, reflecting the potential for total loss of confidentiality, integrity, and availability. Successful exploitation allows an attacker to execute arbitrary code within the context of the browser process, which may lead to unauthorized system access, data theft, or the installation of persistent malware on the user machine.
Remediation
Immediate Action: Update all instances of Mozilla Firefox to version 147.0.2 or later to apply the necessary memory management fixes.
Proactive Monitoring: Monitor endpoint logs for unusual browser crashes or unexpected child process activity that may indicate an attempt to exploit memory corruption vulnerabilities.
Compensating Controls: Ensure that browser security settings are configured to restrict malicious scripts, and utilize endpoint protection platforms to detect and block suspicious code execution attempts.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the severity of this memory safety issue and the potential for remote code execution, organizations should prioritize the deployment of Firefox version 147.0.2 across their environment. Standard browser update cycles should be accelerated to address this critical security gap immediately.
More Mozilla CVEs
Sources
Originally found and disclosed by Hiroyuki Ikezoe, per the CVE Program record.